exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 503 discussion

Actual exam question from CompTIA's SY0-601
Question #: 503
Topic #: 1
[All SY0-601 Questions]

Which of the following can best protect against an employee inadvertently installing malware on a company system?

  • A. Host-based firewall
  • B. System isolation
  • C. Least privilege
  • D. Application allow list
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Chillbuddy
Highly Voted 1 year, 10 months ago
Selected Answer: D
D. Application allow list CompTIA Security+ emphasizes the importance of application control and whitelisting as a strong security practice. An application allow list ensures that only approved and authorized applications can run on a system, effectively preventing the execution of unauthorized or potentially malicious software. This practice aligns with the principle of minimizing attack surfaces and reducing the risk of malware infections caused by inadvertently installing unapproved software. While the principle of least privilege (Option C) is also an important security principle, it focuses on restricting user permissions to the minimum necessary level. Application allow lists provide more direct protection against unauthorized software execution in the context of malware prevention.
upvoted 9 times
...
shocky377
Highly Voted 1 year, 10 months ago
Selected Answer: D
I choose D, since an application allow list lets you only install applications on that list. An employee with least privilege can still install malware on a company if their least privilege allows for installation. Allow list is the only one that will always stop malware installation
upvoted 8 times
...
shady23
Most Recent 1 year, 1 month ago
Selected Answer: C
C. Least privilege All of the options you've listed can contribute to protecting against an employee inadvertently installing malware, but the most effective strategy would likely involve a combination of these measures. However, if we have to choose the one that can best protect against such incidents, "C. Least privilege" stands out.
upvoted 1 times
...
Nemish71
1 year, 1 month ago
Selected Answer: D
An employee can be the admin as well and the admin can download software. But the App allows list that can block all the malicious apps/softwares.
upvoted 2 times
...
shady23
1 year, 1 month ago
Selected Answer: C
Least privilege is a security principle that states that users should only be granted the permissions they need to do their job. This helps to protect against malware infections by preventing users from installing unauthorized software. A host-based firewall can help to protect against malware infections by blocking malicious traffic from reaching a computer. However, it cannot prevent a user from installing malware if they have the necessary permissions.
upvoted 2 times
shady23
1 year, 1 month ago
An application allow list is a list of applications that are allowed to run on a computer. This can help to prevent malware infections by preventing users from running unauthorized applications. However, an application allow list can be difficult to maintain and can block legitimate applications. Therefore, the best way to protect against an employee inadvertently installing malware on a company system is to use the principle of least privilege. This will help to ensure that users only have the permissions they need to do their job, which will reduce the risk of malware infections.
upvoted 2 times
...
...
KC1008
1 year, 3 months ago
Selected Answer: C
Least privilege
upvoted 1 times
...
caseymd85
1 year, 4 months ago
Selected Answer: A
It has to be A or D. Least privilege only makes sense if the employee doesn't have install privs.... The question doesn't state that is the case. It could be the system admin making a mistake. A host based firewall should scan anything attempting to be installed on the host computer and flag it as malicious, thereby stopping it from being installed in the first place. I understand that an allow list may work as well but that assumes that someone hasn't corrupted an allowed application.
upvoted 1 times
...
MortG7
1 year, 5 months ago
NOT C, why? suppose a user's already existing privileges include software installation...how would Least Privilege help? Answer is "D"
upvoted 1 times
...
cyberPunk28
1 year, 6 months ago
Selected Answer: C
C. Least privilege
upvoted 1 times
...
sujon_london
1 year, 9 months ago
Selected Answer: C
The best way to protect against an employee inadvertently installing malware on a company system is to implement the principle of least privilege (option C). This means giving employees only the minimum level of access and permissions necessary to perform their job functions. By limiting their access to only what they need, there is less opportunity for them to inadvertently install malware or make harmful changes to the system. This is a fundamental security practice in protecting against insider threats and reducing the potential impact of security breaches.
upvoted 5 times
...
[Removed]
1 year, 10 months ago
Selected Answer: D
You can implement least privileges but if I am an employee with least standard/admin privileges It won't help I am allowed to install
upvoted 6 times
Abdul2107
1 year, 10 months ago
That's convicing.
upvoted 1 times
...
...
Copmp
1 year, 10 months ago
Selected Answer: C
I would think least privilage would be the answer. as it puts a halt to how much permissions the user would have. Thus halting them from getting into deep water. For the answer to be D, wouldnt the have to know what the malware was to block it?? that would be difficult with zero days existing...
upvoted 1 times
...
ApplebeesWaiter1122
1 year, 11 months ago
Selected Answer: C
The best option to protect against an employee inadvertently installing malware on a company system is to implement the principle of least privilege. Least privilege is the practice of granting users only the minimum level of access and permissions required to perform their job duties and nothing more. By following this principle, employees will have restricted access to sensitive areas of the system, reducing the risk of accidentally installing malicious software. With least privilege, employees won't have unnecessary administrative privileges that could potentially lead to unintended actions, such as installing unauthorized or malicious software. This approach helps prevent the spread of malware and limits the potential damage that could occur if a user's account is compromised or if they inadvertently download and execute harmful files. D is also a good option here but not the best one
upvoted 4 times
...
Gamsje
1 year, 11 months ago
Selected Answer: C
Application allow list does not allow the malware to run. Least privilege does not allow the malware to run too. It can even prevent the employee from downloading the malware. I choose C. Least privilege
upvoted 1 times
...
mtnews
1 year, 11 months ago
Selected Answer: C
I will go with C here
upvoted 1 times
...
LeonardSnart
1 year, 11 months ago
Selected Answer: D
In the real world, yeah I think C would be the answer as least privilege, however at least in the Comptia books I have most refer to the concept in relation to user groups and file/resource access (IE read/write access), rather than what we know in reality to be not allowing standard users to install programs. Since the question says "installing", I'm more likely to go with D here. Just my 2 cents and I'm sure others will disagree.
upvoted 4 times
...
phemendra
1 year, 11 months ago
Selected Answer: C
The principle of least privilege ensures that users are granted only the minimum level of access necessary to perform their job responsibilities. By implementing least privilege, employees have restricted access rights and permissions, limiting their ability to install or execute unauthorized software, including malware.
upvoted 3 times
[Removed]
1 year, 11 months ago
I completely agree with this response for sure!! From experience!
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...